Around 0400 GMT on 16 Jan 2021, an administrator account on the OpenWrt forum (https://forum.openwrt.org) was breached. It is not known how the account was accessed: the account had a good password, but did not have two-factor authentication enabled.
The intruder was able to download a copy of the user list that contains email addresses, handles, and other statistical information about the users of the forum. Although we do not believe the intruder could download the database, from an abundance of caution, we are following the advice of the Discourse community and have reset all passwords on the Forum, and flushed any API keys.
We apologize for the inconvenience caused by this attack. We will provide updates if we learn any more about the attacker or information that was disclosed.
A malicious attacker could send phishing emails to OpenWrt forum users that include their name / OpenWrt forum handle.